Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]


Groups > linux.kernel > #1648416 > unrolled thread

[PATCH 4.11 000/197] 4.11.3-stable review

Started byGreg Kroah-Hartman <gregkh@linuxfoundation.org>
First post2017-05-23 22:20 +0200
Last post2017-05-24 19:00 +0200
Articles 20 on this page of 164 — 3 participants

Back to article view | Back to linux.kernel


Contents

  [PATCH 4.11 000/197] 4.11.3-stable review Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2017-05-23 22:20 +0200
    [PATCH 4.11 022/197] infiniband: call ipv6 route lookup via the stub interface Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2017-05-23 22:20 +0200
    [PATCH 4.11 059/197] drm/nouveau/tmr: avoid processing completed alarms when adding a new one Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2017-05-23 22:20 +0200
    [PATCH 4.11 045/197] regulator: rk808: Fix RK818 LDO2 Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2017-05-23 22:20 +0200
    [PATCH 4.11 075/197] IB/hfi1: Return an error on memory allocation failure Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2017-05-23 22:20 +0200
    [PATCH 4.11 002/197] usb: misc: legousbtower: Fix memory leak Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2017-05-23 22:20 +0200
    [PATCH 4.11 019/197] tpm: fix handling of the TPM 2.0 event logs Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2017-05-23 22:20 +0200
    [PATCH 4.11 080/197] USB: serial: ftdi_sio: add Olimex ARM-USB-TINY(H) PIDs Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2017-05-23 22:20 +0200
    [PATCH 4.11 109/197] iio: hid-sensor: Store restore poll and hysteresis on S3 Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2017-05-23 22:20 +0200
    [PATCH 4.11 110/197] [media] cec: Fix runtime BUG when (CONFIG_RC_CORE && !CEC_CAP_RC) Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2017-05-23 22:20 +0200
    [PATCH 4.11 052/197] drm/amdgpu: Avoid overflows/divide-by-zero in latency_watermark calculations. Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2017-05-23 22:20 +0200
    [PATCH 4.11 007/197] tpm_tis_core: Choose appropriate timeout for reading burstcount Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2017-05-23 22:20 +0200
    [PATCH 4.11 111/197] [media] s5p-mfc: Fix race between interrupt routine and device functions Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2017-05-23 22:20 +0200
    [PATCH 4.11 082/197] Make stat/lstat/fstatat pass AT_NO_AUTOMOUNT to vfs_statx() Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2017-05-23 22:20 +0200
    [PATCH 4.11 071/197] scsi: lpfc: Fix panic on BFS configuration Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2017-05-23 22:20 +0200
    [PATCH 4.11 034/197] dm space map disk: fix some book keeping in the disk space map Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2017-05-23 22:20 +0200
    [PATCH 4.11 117/197] [media] digitv: limit messages to buffer size Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2017-05-23 22:20 +0200
    [PATCH 4.11 008/197] ALSA: hda: Fix cpu lockup when stopping the cmd dmas Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2017-05-23 22:20 +0200
    [PATCH 4.11 087/197] xhci: remove GFP_DMA flag from allocation Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2017-05-23 22:20 +0200
    [PATCH 4.11 106/197] USB: hub: fix non-SS hub-descriptor handling Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2017-05-23 22:20 +0200
    [PATCH 4.11 105/197] USB: hub: fix SS hub-descriptor handling Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2017-05-23 22:20 +0200
    [PATCH 4.11 115/197] [media] zr364xx: enforce minimum size when reading header Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2017-05-23 22:20 +0200
    [PATCH 4.11 036/197] md: MD_CLOSING needs to be cleared after called md_set_readonly or do_md_stop Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2017-05-23 22:20 +0200
    [PATCH 4.11 097/197] usb: dwc3: gadget: Prevent losing events in event cache Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2017-05-23 22:20 +0200
    [PATCH 4.11 050/197] ath9k_htc: fix NULL-deref at probe Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2017-05-23 22:20 +0200
    [PATCH 4.11 093/197] [media] usbvision: fix NULL-deref at probe Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2017-05-23 22:20 +0200
    [PATCH 4.11 058/197] drm/nouveau/tmr: fix corruption of the pending list when rescheduling an alarm Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2017-05-23 22:20 +0200
    [PATCH 4.11 027/197] dm mpath: requeue after a small delay if blk_get_request() fails Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2017-05-23 22:20 +0200
    [PATCH 4.11 029/197] dm mpath: avoid that path removal can trigger an infinite loop Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2017-05-23 22:20 +0200
    [PATCH 4.11 024/197] dm raid: select the Kconfig option CONFIG_MD_RAID0 Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2017-05-23 22:20 +0200
    [PATCH 4.11 023/197] dm btree: fix for dm_btree_find_lowest_key() Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2017-05-23 22:20 +0200
    [PATCH 4.11 031/197] dm cache metadata: fail operations if fail_io mode has been established Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2017-05-23 22:20 +0200
    [PATCH 4.11 092/197] net: irda: irda-usb: fix firmware name on big-endian hosts Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2017-05-23 22:20 +0200
    [PATCH 4.11 001/197] usb: misc: legousbtower: Fix buffers on stack Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2017-05-23 22:20 +0200
    [PATCH 4.11 020/197] ASoC: cs4271: configure reset GPIO as output Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2017-05-23 22:20 +0200
    [PATCH 4.11 124/197] powerpc/book3s/mce: Move add_taint() later in virtual mode Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2017-05-23 22:30 +0200
    [PATCH 4.11 169/197] osf_wait4(): fix infoleak Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2017-05-23 22:30 +0200
    [PATCH 4.11 156/197] staging: rtl8192e: GetTs Fix invalid TID 7 warning. Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2017-05-23 22:30 +0200
    [PATCH 4.11 139/197] ARM: 8670/1: V7M: Do not corrupt vector table around v7m_invalidate_l1 call Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2017-05-23 22:30 +0200
    [PATCH 4.11 184/197] mtd: nand: omap2: Fix partition creation via cmdline mtdparts Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2017-05-23 22:30 +0200
    [PATCH 4.11 155/197] staging: rtl8192e: rtl92e_get_eeprom_size Fix read size of EPROM_CMD. Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2017-05-23 22:30 +0200
    [PATCH 4.11 164/197] nvme: unmap CMB and remove sysfs file in reset path Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2017-05-23 22:30 +0200
    [PATCH 4.11 144/197] arm64: xchg: hazard against entire exchange variable Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2017-05-23 22:30 +0200
    [PATCH 4.11 142/197] ARM: dts: imx6sx-sdb: Remove OPP override Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2017-05-23 22:30 +0200
    [PATCH 4.11 195/197] drivers: char: mem: Check for address space wraparound with mmap() Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2017-05-23 22:30 +0200
    [PATCH 4.11 193/197] nfsd: encoders mustnt use unitialized values in error cases Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2017-05-23 22:30 +0200
    [PATCH 4.11 133/197] arm: KVM: Do not use stack-protector to compile HYP code Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2017-05-23 22:30 +0200
    [PATCH 4.11 157/197] iommu/vt-d: Flush the IOTLB to get rid of the initial kdump mappings Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2017-05-23 22:30 +0200
    [PATCH 4.11 138/197] ARM: 8667/3: Fix memory attribute inconsistencies when using fixmap Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2017-05-23 22:30 +0200
    [PATCH 4.11 134/197] KVM: arm/arm64: vgic-v2: Do not use Active+Pending state for a HW interrupt Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2017-05-23 22:30 +0200
    [PATCH 4.11 181/197] PCI: Only allow WC mmap on prefetchable resources Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2017-05-23 22:30 +0200
    [PATCH 4.11 130/197] powerpc/mm: Fix crash in page table dump with huge pages Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2017-05-23 22:30 +0200
    [PATCH 4.11 188/197] NFS: Fix use after free in write error path Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2017-05-23 22:30 +0200
    [PATCH 4.11 160/197] metag/uaccess: Check access_ok in strncpy_from_user Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2017-05-23 22:30 +0200
    [PATCH 4.11 128/197] powerpc/powernv: Fix TCE kill on NVLink2 Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2017-05-23 22:30 +0200
    Re: [PATCH 4.11 044/197] x86: fix 32-bit case of __get_user_asm_u64() Linus Torvalds <torvalds@linux-foundation.org> - 2017-05-23 22:30 +0200
    [PATCH 4.11 146/197] arm64: armv8_deprecated: ensure extension of addr Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2017-05-23 22:30 +0200
    [PATCH 4.11 196/197] drm/i915/gvt: Disable access to stolen memory as a guest Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2017-05-23 22:30 +0200
    [PATCH 4.11 150/197] arm64: entry: improve data abort handling of tagged pointers Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2017-05-23 22:30 +0200
    [PATCH 4.11 173/197] tracing/kprobes: Enforce kprobes teardown after testing Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2017-05-23 22:30 +0200
    [PATCH 4.11 174/197] thermal: mt8173: minor mtk_thermal.c cleanups Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2017-05-23 22:30 +0200
    [PATCH 4.11 185/197] mtd: nand: add ooblayout for old hamming layout Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2017-05-23 22:30 +0200
    [PATCH 4.11 137/197] ARM: 8662/1: module: split core and init PLT sections Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2017-05-23 22:30 +0200
    [PATCH 4.11 187/197] NFSv4: Fix a hang in OPEN related to server reboot Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2017-05-23 22:30 +0200
    [PATCH 4.11 186/197] drm/edid: Add 10 bpc quirk for LGD 764 panel in HP zBook 17 G2 Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2017-05-23 22:30 +0200
    [PATCH 4.11 129/197] powerpc/64e: Fix hang when debugging programs with relocated kernel Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2017-05-23 22:30 +0200
    [PATCH 4.11 172/197] firmware: ti_sci: fix strncat length check Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2017-05-23 22:30 +0200
    [PATCH 4.11 179/197] PCI: Fix pci_mmap_fits() for HAVE_PCI_RESOURCE_TO_USER platforms Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2017-05-23 22:30 +0200
    [PATCH 4.11 148/197] arm64: traps: fix userspace cache maintenance emulation on a tagged pointer Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2017-05-23 22:30 +0200
    [PATCH 4.11 158/197] cpuidle: check dev before usage in cpuidle_use_deepest_state() Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2017-05-23 23:10 +0200
    [PATCH 4.11 191/197] NFSv4: Fix an rcu lock leak Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2017-05-24 00:00 +0200
    [PATCH 4.11 197/197] IB/hfi1: Protect the global dev_cntr_names and port_cntr_names Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2017-05-24 00:00 +0200
    [PATCH 4.11 194/197] nfsd: Fix up the "supattr_exclcreat" attributes Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2017-05-24 00:00 +0200
    [PATCH 4.11 190/197] pNFS/flexfiles: Check the result of nfs4_pnfs_ds_connect Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2017-05-24 00:00 +0200
    [PATCH 4.11 165/197] MIPS: Loongson-3: Select MIPS_L1_CACHE_SHIFT_6 Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2017-05-24 00:00 +0200
    [PATCH 4.11 159/197] metag/uaccess: Fix access_ok() Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2017-05-24 00:00 +0200
    [PATCH 4.11 168/197] kvm: arm/arm64: Force reading uncached stage2 PGD Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2017-05-24 00:00 +0200
    [PATCH 4.11 192/197] nfsd: fix undefined behavior in nfsd4_layout_verify Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2017-05-24 00:00 +0200
    [PATCH 4.11 176/197] PCI/ACPI: Add ThunderX pass2.x 2nd node MCFG quirk Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2017-05-24 00:10 +0200
    [PATCH 4.11 120/197] [media] cx231xx-audio: fix NULL-deref at probe Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2017-05-24 00:10 +0200
    [PATCH 4.11 178/197] PCI: hv: Specify CPU_AFFINITY_ALL for MSI affinity when >= 32 CPUs Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2017-05-24 00:10 +0200
    [PATCH 4.11 149/197] arm64: hw_breakpoint: fix watchpoint matching for tagged pointers Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2017-05-24 00:10 +0200
    [PATCH 4.11 183/197] mtd: nand: orion: fix clk handling Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2017-05-24 00:10 +0200
    [PATCH 4.11 177/197] PCI: hv: Allocate interrupt descriptors with GFP_ATOMIC Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2017-05-24 00:10 +0200
    [PATCH 4.11 180/197] PCI: Fix another sanity check bug in /proc/pci mmap Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2017-05-24 00:10 +0200
    [PATCH 4.11 127/197] powerpc/iommu: Do not call PageTransHuge() on tail pages Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2017-05-24 00:10 +0200
    [PATCH 4.11 152/197] staging: vc04_services: Fix bulk cache maintenance Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2017-05-24 00:10 +0200
    [PATCH 4.11 162/197] uwb: fix device quirk on big-endian hosts Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2017-05-24 00:10 +0200
    [PATCH 4.11 153/197] staging: rtl8192e: rtl92e_fill_tx_desc fix write to mapped out memory. Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2017-05-24 00:10 +0200
    [PATCH 4.11 151/197] arm64: documentation: document tagged pointer stack constraints Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2017-05-24 00:10 +0200
    [PATCH 4.11 170/197] drbd: fix request leak introduced by locking/atomic, kref: Kill kref_sub() Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2017-05-24 00:10 +0200
    [PATCH 4.11 161/197] stackprotector: Increase the per-task stack canarys random range from 32 bits to 64 bits on 64-bit platforms Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2017-05-24 00:10 +0200
    [PATCH 4.11 171/197] um: Fix to call read_initrd after init_bootmem Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2017-05-24 00:10 +0200
    [PATCH 4.11 175/197] PCI/ACPI: Tidy up MCFG quirk whitespace Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2017-05-24 00:10 +0200
    [PATCH 4.11 189/197] NFS: Use GFP_NOIO for two allocations in writeback Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2017-05-24 00:10 +0200
    [PATCH 4.11 163/197] genirq: Fix chained interrupt data ordering Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2017-05-24 00:10 +0200
    [PATCH 4.11 154/197] staging: rtl8192e: fix 2 byte alignment of register BSSIDR. Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2017-05-24 00:10 +0200
    [PATCH 4.11 125/197] powerpc/pseries: Fix of_node_put() underflow during DLPAR remove Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2017-05-24 00:10 +0200
    [PATCH 4.11 126/197] powerpc/sysfs: Fix reference leak of cpu device_nodes present at boot Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2017-05-24 00:10 +0200
    [PATCH 4.11 145/197] arm64: ensure extension of smp_store_release value Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2017-05-24 00:20 +0200
    [PATCH 4.11 147/197] arm64: uaccess: ensure extension of access_ok() addr Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2017-05-24 00:20 +0200
    [PATCH 4.11 114/197] [media] dib0700: fix NULL-deref at probe Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2017-05-24 00:20 +0200
    [PATCH 4.11 118/197] [media] dw2102: limit messages to buffer size Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2017-05-24 00:20 +0200
    [PATCH 4.11 101/197] usb: serial: option: add Telit ME910 support Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2017-05-24 00:20 +0200
    [PATCH 4.11 091/197] usb: host: xhci-mem: allocate zeroed Scratchpad Buffer Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2017-05-24 00:20 +0200
    [PATCH 4.11 103/197] USB: serial: mct_u232: fix big-endian baud-rate handling Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2017-05-24 00:20 +0200
    [PATCH 4.11 090/197] xhci: apply PME_STUCK_QUIRK and MISSING_CAS quirk for Denverton Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2017-05-24 00:20 +0200
    [PATCH 4.11 086/197] xhci: Fix command ring stop regression in 4.11 Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2017-05-24 00:20 +0200
    [PATCH 4.11 108/197] iio: proximity: as3935: fix as3935_write Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2017-05-24 00:20 +0200
    [PATCH 4.11 141/197] ARM: dts: at91: sama5d3_xplained: not all ADC channels are available Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2017-05-24 00:20 +0200
    [PATCH 4.11 135/197] KVM: arm/arm64: vgic-v3: Do not use Active+Pending state for a HW interrupt Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2017-05-24 00:20 +0200
    [PATCH 4.11 143/197] arm64: dts: hi6220: Reset the mmc hosts Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2017-05-24 00:20 +0200
    [PATCH 4.11 122/197] powerpc/mm: Ensure IRQs are off in switch_mm() Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2017-05-24 00:20 +0200
    [PATCH 4.11 116/197] [media] dvb-frontends/cxd2841er: define symbol_rate_min/max in T/C fe-ops Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2017-05-24 00:20 +0200
    [PATCH 4.11 121/197] [media] cx231xx-cards: fix NULL-deref at probe Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2017-05-24 00:20 +0200
    [PATCH 4.11 131/197] powerpc/tm: Fix FP and VMX register corruption Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2017-05-24 00:20 +0200
    [PATCH 4.11 123/197] powerpc/eeh: Avoid use after free in eeh_handle_special_event() Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2017-05-24 00:20 +0200
    [PATCH 4.11 104/197] USB: serial: io_ti: fix div-by-zero in set_termios Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2017-05-24 00:20 +0200
    [PATCH 4.11 119/197] [media] cx231xx-audio: fix init error path Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2017-05-24 00:20 +0200
    [PATCH 4.11 113/197] [media] s5p-mfc: Fix unbalanced call to clock management Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2017-05-24 00:20 +0200
    [PATCH 4.11 140/197] ARM: dts: at91: sama5d3_xplained: fix ADC vref Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2017-05-24 00:20 +0200
    [PATCH 4.11 132/197] arm64: KVM: Do not use stack-protector to compile EL2 code Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2017-05-24 00:20 +0200
    [PATCH 4.11 072/197] iio: dac: ad7303: fix channel description Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2017-05-24 00:30 +0200
    [PATCH 4.11 061/197] gpio: omap: return error if requested debounce time is not possible Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2017-05-24 00:30 +0200
    [PATCH 4.11 076/197] IB/hfi1: Fix a subcontext memory leak Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2017-05-24 00:30 +0200
    [PATCH 4.11 014/197] tpm_tis_spi: Add small delay after last transfer Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2017-05-24 00:30 +0200
    [PATCH 4.11 073/197] IIO: bmp280-core.c: fix error in humidity calculation Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2017-05-24 00:30 +0200
    [PATCH 4.11 021/197] mlx5: Fix mlx5_ib_map_mr_sg mr length Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2017-05-24 00:30 +0200
    [PATCH 4.11 054/197] drm/nouveau/therm: remove ineffective workarounds for alarm bugs Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2017-05-24 00:30 +0200
    [PATCH 4.11 096/197] [media] dvb-usb-dibusb-mc-common: Add MODULE_LICENSE Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2017-05-24 00:30 +0200
    [PATCH 4.11 047/197] s390/kdump: Add final note Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2017-05-24 00:30 +0200
    [PATCH 4.11 081/197] USB: chaoskey: fix Alea quirk on big-endian hosts Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2017-05-24 00:30 +0200
    [PATCH 4.11 044/197] x86: fix 32-bit case of __get_user_asm_u64() Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2017-05-24 00:30 +0200
    [PATCH 4.11 074/197] iio: stm32 trigger: fix sampling_frequency read Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2017-05-24 00:30 +0200
    [PATCH 4.11 100/197] USB: iowarrior: fix info ioctl on big-endian hosts Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2017-05-24 00:30 +0200
    [PATCH 4.11 064/197] cxl: Force context lock during EEH flow Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2017-05-24 00:30 +0200
    [PATCH 4.11 083/197] libnvdimm: fix clear length of nvdimm_forget_poison() Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2017-05-24 00:30 +0200
    [PATCH 4.11 057/197] drm/nouveau/tmr: ack interrupt before processing alarms Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2017-05-24 00:30 +0200
    [PATCH 4.11 095/197] [media] ttusb2: limit messages to buffer size Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2017-05-24 00:30 +0200
    [PATCH 4.11 048/197] s390/cputime: fix incorrect system time Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2017-05-24 00:30 +0200
    [PATCH 4.11 078/197] pid_ns: Fix race between setnsed fork() and zap_pid_ns_processes() Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2017-05-24 00:30 +0200
    [PATCH 4.11 070/197] ibmvscsis: Do not send aborted task response Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2017-05-24 00:30 +0200
    [PATCH 4.11 067/197] of: fix sparse warning in of_pci_range_parser_one Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2017-05-24 00:30 +0200
    [PATCH 4.11 062/197] cdc-acm: fix possible invalid access when processing notification Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2017-05-24 00:30 +0200
    [PATCH 4.11 039/197] mwifiex: pcie: fix cmd_buf use-after-free in remove/reset Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2017-05-24 00:30 +0200
    [PATCH 4.11 055/197] drm/nouveau/kms/nv50: fix source-rect-only plane updates Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2017-05-24 00:30 +0200
    [PATCH 4.11 018/197] vTPM: Fix missing NULL check Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2017-05-24 00:30 +0200
    [PATCH 4.11 060/197] drm/nouveau/tmr: handle races with hw when updating the next alarm time Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2017-05-24 00:30 +0200
    [PATCH 4.11 051/197] drm/amdgpu: Make display watermark calculations more accurate Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2017-05-24 00:30 +0200
    [PATCH 4.11 009/197] fanotify: dont expose EOPENSTALE to userspace Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2017-05-24 00:40 +0200
    [PATCH 4.11 025/197] dm bufio: avoid a possible ABBA deadlock Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2017-05-24 00:40 +0200
    [PATCH 4.11 003/197] USB: ene_usb6250: fix DMA to the stack Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2017-05-24 00:40 +0200
    [PATCH 4.11 012/197] tpm_tis_spi: Check correct byte for wait state indicator Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2017-05-24 00:40 +0200
    [PATCH 4.11 006/197] USB: core: replace %p with %pK Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2017-05-24 00:40 +0200
    [PATCH 4.11 013/197] tpm_tis_spi: Remove limitation of transfers to MAX_SPI_FRAMESIZE bytes Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2017-05-24 00:40 +0200
    [PATCH 4.11 033/197] dm thin metadata: call precommit before saving the roots Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2017-05-24 00:40 +0200
    [PATCH 4.11 026/197] dm bufio: check new buffer allocation watermark every 30 seconds Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2017-05-24 00:40 +0200
    [PATCH 4.11 028/197] dm mpath: split and rename activate_path() to prepare for its expanded use Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2017-05-24 00:40 +0200
    [PATCH 4.11 037/197] rtlwifi: rtl8821ae: setup 8812ae RFE according to device type Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2017-05-24 00:40 +0200
    [PATCH 4.11 015/197] tpm: msleep() delays - replace with usleep_range() in i2c nuvoton driver Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2017-05-24 00:40 +0200
    [PATCH 4.11 035/197] md: update slab_cache before releasing new stripes when stripes resizing Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2017-05-24 00:40 +0200
    [PATCH 4.11 030/197] dm mpath: delay requeuing while path initialization is in progress Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2017-05-24 00:40 +0200
    [PATCH 4.11 005/197] char: lp: fix possible integer overflow in lp_setup() Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2017-05-24 00:40 +0200
    Re: [PATCH 4.11 000/197] 4.11.3-stable review Guenter Roeck <linux@roeck-us.net> - 2017-05-24 19:00 +0200

Page 6 of 9 — ← Prev page 1 2 3 4 5 [6] 7 8 9  Next page →


#1648914 — [PATCH 4.11 147/197] arm64: uaccess: ensure extension of access_ok() addr

FromGreg Kroah-Hartman <gregkh@linuxfoundation.org>
Date2017-05-24 00:20 +0200
Subject[PATCH 4.11 147/197] arm64: uaccess: ensure extension of access_ok() addr
Message-ID<tKqjL-1dD-3@gated-at.bofh.it>
In reply to#1648416
4.11-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Mark Rutland <mark.rutland@arm.com>

commit a06040d7a791a9177581dcf7293941bd92400856 upstream.

Our access_ok() simply hands its arguments over to __range_ok(), which
implicitly assummes that the addr parameter is 64 bits wide. This isn't
necessarily true for compat code, which might pass down a 32-bit address
parameter.

In these cases, we don't have a guarantee that the address has been zero
extended to 64 bits, and the upper bits of the register may contain
unknown values, potentially resulting in a suprious failure.

Avoid this by explicitly casting the addr parameter to an unsigned long
(as is done on other architectures), ensuring that the parameter is
widened appropriately.

Fixes: 0aea86a2176c ("arm64: User access library functions")
Acked-by: Will Deacon <will.deacon@arm.com>
Signed-off-by: Mark Rutland <mark.rutland@arm.com>
Signed-off-by: Catalin Marinas <catalin.marinas@arm.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>

---
 arch/arm64/include/asm/uaccess.h |    3 ++-
 1 file changed, 2 insertions(+), 1 deletion(-)

--- a/arch/arm64/include/asm/uaccess.h
+++ b/arch/arm64/include/asm/uaccess.h
@@ -95,11 +95,12 @@ static inline void set_fs(mm_segment_t f
  */
 #define __range_ok(addr, size)						\
 ({									\
+	unsigned long __addr = (unsigned long __force)(addr);		\
 	unsigned long flag, roksum;					\
 	__chk_user_ptr(addr);						\
 	asm("adds %1, %1, %3; ccmp %1, %4, #2, cc; cset %0, ls"		\
 		: "=&r" (flag), "=&r" (roksum)				\
-		: "1" (addr), "Ir" (size),				\
+		: "1" (__addr), "Ir" (size),				\
 		  "r" (current_thread_info()->addr_limit)		\
 		: "cc");						\
 	flag;								\

[toc] | [prev] | [next] | [standalone]


#1648915 — [PATCH 4.11 114/197] [media] dib0700: fix NULL-deref at probe

FromGreg Kroah-Hartman <gregkh@linuxfoundation.org>
Date2017-05-24 00:20 +0200
Subject[PATCH 4.11 114/197] [media] dib0700: fix NULL-deref at probe
Message-ID<tKqjL-1dD-5@gated-at.bofh.it>
In reply to#1648416
4.11-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Johan Hovold <johan@kernel.org>

commit d5823511c0f8719a39e72ede1bce65411ac653b7 upstream.

Make sure to check the number of endpoints to avoid dereferencing a
NULL-pointer should a malicious device lack endpoints.

Fixes: c4018fa2e4c0 ("[media] dib0700: fix RC support on Hauppauge
Nova-TD")

Cc: Mauro Carvalho Chehab <mchehab@kernel.org>
Signed-off-by: Johan Hovold <johan@kernel.org>
Signed-off-by: Hans Verkuil <hans.verkuil@cisco.com>
Signed-off-by: Mauro Carvalho Chehab <mchehab@s-opensource.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>

---
 drivers/media/usb/dvb-usb/dib0700_core.c |    3 +++
 1 file changed, 3 insertions(+)

--- a/drivers/media/usb/dvb-usb/dib0700_core.c
+++ b/drivers/media/usb/dvb-usb/dib0700_core.c
@@ -809,6 +809,9 @@ int dib0700_rc_setup(struct dvb_usb_devi
 
 	/* Starting in firmware 1.20, the RC info is provided on a bulk pipe */
 
+	if (intf->altsetting[0].desc.bNumEndpoints < rc_ep + 1)
+		return -ENODEV;
+
 	purb = usb_alloc_urb(0, GFP_KERNEL);
 	if (purb == NULL)
 		return -ENOMEM;

[toc] | [prev] | [next] | [standalone]


#1648916 — [PATCH 4.11 118/197] [media] dw2102: limit messages to buffer size

FromGreg Kroah-Hartman <gregkh@linuxfoundation.org>
Date2017-05-24 00:20 +0200
Subject[PATCH 4.11 118/197] [media] dw2102: limit messages to buffer size
Message-ID<tKqjL-1dD-7@gated-at.bofh.it>
In reply to#1648416
4.11-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Alyssa Milburn <amilburn@zall.org>

commit 950e252cb469f323740d78e4907843acef89eedb upstream.

Otherwise the i2c transfer functions can read or write beyond the end of
stack or heap buffers.

Signed-off-by: Alyssa Milburn <amilburn@zall.org>
Signed-off-by: Mauro Carvalho Chehab <mchehab@s-opensource.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>

---
 drivers/media/usb/dvb-usb/dw2102.c |   54 +++++++++++++++++++++++++++++++++++++
 1 file changed, 54 insertions(+)

--- a/drivers/media/usb/dvb-usb/dw2102.c
+++ b/drivers/media/usb/dvb-usb/dw2102.c
@@ -204,6 +204,20 @@ static int dw2102_serit_i2c_transfer(str
 
 	switch (num) {
 	case 2:
+		if (msg[0].len != 1) {
+			warn("i2c rd: len=%d is not 1!\n",
+			     msg[0].len);
+			num = -EOPNOTSUPP;
+			break;
+		}
+
+		if (2 + msg[1].len > sizeof(buf6)) {
+			warn("i2c rd: len=%d is too big!\n",
+			     msg[1].len);
+			num = -EOPNOTSUPP;
+			break;
+		}
+
 		/* read si2109 register by number */
 		buf6[0] = msg[0].addr << 1;
 		buf6[1] = msg[0].len;
@@ -219,6 +233,13 @@ static int dw2102_serit_i2c_transfer(str
 	case 1:
 		switch (msg[0].addr) {
 		case 0x68:
+			if (2 + msg[0].len > sizeof(buf6)) {
+				warn("i2c wr: len=%d is too big!\n",
+				     msg[0].len);
+				num = -EOPNOTSUPP;
+				break;
+			}
+
 			/* write to si2109 register */
 			buf6[0] = msg[0].addr << 1;
 			buf6[1] = msg[0].len;
@@ -262,6 +283,13 @@ static int dw2102_earda_i2c_transfer(str
 		/* first write first register number */
 		u8 ibuf[MAX_XFER_SIZE], obuf[3];
 
+		if (2 + msg[0].len != sizeof(obuf)) {
+			warn("i2c rd: len=%d is not 1!\n",
+			     msg[0].len);
+			ret = -EOPNOTSUPP;
+			goto unlock;
+		}
+
 		if (2 + msg[1].len > sizeof(ibuf)) {
 			warn("i2c rd: len=%d is too big!\n",
 			     msg[1].len);
@@ -462,6 +490,12 @@ static int dw3101_i2c_transfer(struct i2
 		/* first write first register number */
 		u8 ibuf[MAX_XFER_SIZE], obuf[3];
 
+		if (2 + msg[0].len != sizeof(obuf)) {
+			warn("i2c rd: len=%d is not 1!\n",
+			     msg[0].len);
+			ret = -EOPNOTSUPP;
+			goto unlock;
+		}
 		if (2 + msg[1].len > sizeof(ibuf)) {
 			warn("i2c rd: len=%d is too big!\n",
 			     msg[1].len);
@@ -696,6 +730,13 @@ static int su3000_i2c_transfer(struct i2
 			msg[0].buf[0] = state->data[1];
 			break;
 		default:
+			if (3 + msg[0].len > sizeof(state->data)) {
+				warn("i2c wr: len=%d is too big!\n",
+				     msg[0].len);
+				num = -EOPNOTSUPP;
+				break;
+			}
+
 			/* always i2c write*/
 			state->data[0] = 0x08;
 			state->data[1] = msg[0].addr;
@@ -711,6 +752,19 @@ static int su3000_i2c_transfer(struct i2
 		break;
 	case 2:
 		/* always i2c read */
+		if (4 + msg[0].len > sizeof(state->data)) {
+			warn("i2c rd: len=%d is too big!\n",
+			     msg[0].len);
+			num = -EOPNOTSUPP;
+			break;
+		}
+		if (1 + msg[1].len > sizeof(state->data)) {
+			warn("i2c rd: len=%d is too big!\n",
+			     msg[1].len);
+			num = -EOPNOTSUPP;
+			break;
+		}
+
 		state->data[0] = 0x09;
 		state->data[1] = msg[0].len;
 		state->data[2] = msg[1].len;

[toc] | [prev] | [next] | [standalone]


#1648919 — [PATCH 4.11 101/197] usb: serial: option: add Telit ME910 support

FromGreg Kroah-Hartman <gregkh@linuxfoundation.org>
Date2017-05-24 00:20 +0200
Subject[PATCH 4.11 101/197] usb: serial: option: add Telit ME910 support
Message-ID<tKqjM-1dD-19@gated-at.bofh.it>
In reply to#1648416
4.11-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Daniele Palmas <dnlplm@gmail.com>

commit 40dd46048c155b8f0683f468c950a1c107f77a7c upstream.

This patch adds support for Telit ME910 PID 0x1100.

Signed-off-by: Daniele Palmas <dnlplm@gmail.com>
Signed-off-by: Johan Hovold <johan@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>

---
 drivers/usb/serial/option.c |    8 ++++++++
 1 file changed, 8 insertions(+)

--- a/drivers/usb/serial/option.c
+++ b/drivers/usb/serial/option.c
@@ -281,6 +281,7 @@ static void option_instat_callback(struc
 #define TELIT_PRODUCT_LE922_USBCFG0		0x1042
 #define TELIT_PRODUCT_LE922_USBCFG3		0x1043
 #define TELIT_PRODUCT_LE922_USBCFG5		0x1045
+#define TELIT_PRODUCT_ME910			0x1100
 #define TELIT_PRODUCT_LE920			0x1200
 #define TELIT_PRODUCT_LE910			0x1201
 #define TELIT_PRODUCT_LE910_USBCFG4		0x1206
@@ -640,6 +641,11 @@ static const struct option_blacklist_inf
 	.reserved = BIT(5) | BIT(6),
 };
 
+static const struct option_blacklist_info telit_me910_blacklist = {
+	.sendsetup = BIT(0),
+	.reserved = BIT(1) | BIT(3),
+};
+
 static const struct option_blacklist_info telit_le910_blacklist = {
 	.sendsetup = BIT(0),
 	.reserved = BIT(1) | BIT(2),
@@ -1235,6 +1241,8 @@ static const struct usb_device_id option
 		.driver_info = (kernel_ulong_t)&telit_le922_blacklist_usbcfg3 },
 	{ USB_DEVICE_INTERFACE_CLASS(TELIT_VENDOR_ID, TELIT_PRODUCT_LE922_USBCFG5, 0xff),
 		.driver_info = (kernel_ulong_t)&telit_le922_blacklist_usbcfg0 },
+	{ USB_DEVICE(TELIT_VENDOR_ID, TELIT_PRODUCT_ME910),
+		.driver_info = (kernel_ulong_t)&telit_me910_blacklist },
 	{ USB_DEVICE(TELIT_VENDOR_ID, TELIT_PRODUCT_LE910),
 		.driver_info = (kernel_ulong_t)&telit_le910_blacklist },
 	{ USB_DEVICE(TELIT_VENDOR_ID, TELIT_PRODUCT_LE910_USBCFG4),

[toc] | [prev] | [next] | [standalone]


#1648920 — [PATCH 4.11 091/197] usb: host: xhci-mem: allocate zeroed Scratchpad Buffer

FromGreg Kroah-Hartman <gregkh@linuxfoundation.org>
Date2017-05-24 00:20 +0200
Subject[PATCH 4.11 091/197] usb: host: xhci-mem: allocate zeroed Scratchpad Buffer
Message-ID<tKqjL-1dD-15@gated-at.bofh.it>
In reply to#1648416
4.11-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Peter Chen <peter.chen@nxp.com>

commit 7480d912d549f414e0ce39331870899e89a5598c upstream.

According to xHCI ch4.20 Scratchpad Buffers, the Scratchpad
Buffer needs to be zeroed.

	...
	The following operations take place to allocate
       	Scratchpad Buffers to the xHC:
	...
		b. Software clears the Scratchpad Buffer to '0'

Signed-off-by: Peter Chen <peter.chen@nxp.com>
Signed-off-by: Mathias Nyman <mathias.nyman@linux.intel.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>

---
 drivers/usb/host/xhci-mem.c |    2 +-
 1 file changed, 1 insertion(+), 1 deletion(-)

--- a/drivers/usb/host/xhci-mem.c
+++ b/drivers/usb/host/xhci-mem.c
@@ -1729,7 +1729,7 @@ static int scratchpad_alloc(struct xhci_
 	xhci->dcbaa->dev_context_ptrs[0] = cpu_to_le64(xhci->scratchpad->sp_dma);
 	for (i = 0; i < num_sp; i++) {
 		dma_addr_t dma;
-		void *buf = dma_alloc_coherent(dev, xhci->page_size, &dma,
+		void *buf = dma_zalloc_coherent(dev, xhci->page_size, &dma,
 				flags);
 		if (!buf)
 			goto fail_sp5;

[toc] | [prev] | [next] | [standalone]


#1648921 — [PATCH 4.11 103/197] USB: serial: mct_u232: fix big-endian baud-rate handling

FromGreg Kroah-Hartman <gregkh@linuxfoundation.org>
Date2017-05-24 00:20 +0200
Subject[PATCH 4.11 103/197] USB: serial: mct_u232: fix big-endian baud-rate handling
Message-ID<tKqjL-1dD-17@gated-at.bofh.it>
In reply to#1648416
4.11-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Johan Hovold <johan@kernel.org>

commit 26cede343656c0bc2c33cdc783771282405c7fb2 upstream.

Drop erroneous cpu_to_le32 when setting the baud rate, something which
corrupted the divisor on big-endian hosts.

Found using sparse:

	warning: incorrect type in argument 1 (different base types)
	    expected unsigned int [unsigned] [usertype] val
	    got restricted __le32 [usertype] <noident>

Fixes: af2ac1a091bc ("USB: serial mct_usb232: move DMA buffers to heap")
Reviewed-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
Acked-By: Pete Zaitcev <zaitcev@yahoo.com>
Signed-off-by: Johan Hovold <johan@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>

---
 drivers/usb/serial/mct_u232.c |    2 +-
 1 file changed, 1 insertion(+), 1 deletion(-)

--- a/drivers/usb/serial/mct_u232.c
+++ b/drivers/usb/serial/mct_u232.c
@@ -189,7 +189,7 @@ static int mct_u232_set_baud_rate(struct
 		return -ENOMEM;
 
 	divisor = mct_u232_calculate_baud_rate(serial, value, &speed);
-	put_unaligned_le32(cpu_to_le32(divisor), buf);
+	put_unaligned_le32(divisor, buf);
 	rc = usb_control_msg(serial->dev, usb_sndctrlpipe(serial->dev, 0),
 				MCT_U232_SET_BAUD_RATE_REQUEST,
 				MCT_U232_SET_REQUEST_TYPE,

[toc] | [prev] | [next] | [standalone]


#1648922 — [PATCH 4.11 090/197] xhci: apply PME_STUCK_QUIRK and MISSING_CAS quirk for Denverton

FromGreg Kroah-Hartman <gregkh@linuxfoundation.org>
Date2017-05-24 00:20 +0200
Subject[PATCH 4.11 090/197] xhci: apply PME_STUCK_QUIRK and MISSING_CAS quirk for Denverton
Message-ID<tKqjM-1dD-21@gated-at.bofh.it>
In reply to#1648416
4.11-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Mathias Nyman <mathias.nyman@linux.intel.com>

commit a0c16630d35a874e82bdf2088f58ecaca1024315 upstream.

Intel Denverton microserver is Atom based and need the PME and CAS quirks
as well.

Signed-off-by: Mathias Nyman <mathias.nyman@linux.intel.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>

---
 drivers/usb/host/xhci-pci.c |    7 +++++--
 1 file changed, 5 insertions(+), 2 deletions(-)

--- a/drivers/usb/host/xhci-pci.c
+++ b/drivers/usb/host/xhci-pci.c
@@ -52,6 +52,7 @@
 #define PCI_DEVICE_ID_INTEL_BROXTON_M_XHCI		0x0aa8
 #define PCI_DEVICE_ID_INTEL_BROXTON_B_XHCI		0x1aa8
 #define PCI_DEVICE_ID_INTEL_APL_XHCI			0x5aa8
+#define PCI_DEVICE_ID_INTEL_DNV_XHCI			0x19d0
 
 static const char hcd_name[] = "xhci_hcd";
 
@@ -166,7 +167,8 @@ static void xhci_pci_quirks(struct devic
 		 pdev->device == PCI_DEVICE_ID_INTEL_CHERRYVIEW_XHCI ||
 		 pdev->device == PCI_DEVICE_ID_INTEL_BROXTON_M_XHCI ||
 		 pdev->device == PCI_DEVICE_ID_INTEL_BROXTON_B_XHCI ||
-		 pdev->device == PCI_DEVICE_ID_INTEL_APL_XHCI)) {
+		 pdev->device == PCI_DEVICE_ID_INTEL_APL_XHCI ||
+		 pdev->device == PCI_DEVICE_ID_INTEL_DNV_XHCI)) {
 		xhci->quirks |= XHCI_PME_STUCK_QUIRK;
 	}
 	if (pdev->vendor == PCI_VENDOR_ID_INTEL &&
@@ -175,7 +177,8 @@ static void xhci_pci_quirks(struct devic
 	}
 	if (pdev->vendor == PCI_VENDOR_ID_INTEL &&
 	    (pdev->device == PCI_DEVICE_ID_INTEL_CHERRYVIEW_XHCI ||
-	     pdev->device == PCI_DEVICE_ID_INTEL_APL_XHCI))
+	     pdev->device == PCI_DEVICE_ID_INTEL_APL_XHCI ||
+	     pdev->device == PCI_DEVICE_ID_INTEL_DNV_XHCI))
 		xhci->quirks |= XHCI_MISSING_CAS;
 
 	if (pdev->vendor == PCI_VENDOR_ID_ETRON &&

[toc] | [prev] | [next] | [standalone]


#1648924 — [PATCH 4.11 086/197] xhci: Fix command ring stop regression in 4.11

FromGreg Kroah-Hartman <gregkh@linuxfoundation.org>
Date2017-05-24 00:20 +0200
Subject[PATCH 4.11 086/197] xhci: Fix command ring stop regression in 4.11
Message-ID<tKqjM-1dD-23@gated-at.bofh.it>
In reply to#1648416
4.11-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Mathias Nyman <mathias.nyman@linux.intel.com>

commit 604d02a2a66ab7f93fd3b2bde3698c29ef057b65 upstream.

In 4.11 TRB completion codes were renamed to match spec.

Completion codes for command ring stopped and endpoint stopped
were mixed, leading to failures while handling a stopped command ring.

Use the correct completion code for command ring stopped events.

Fixes: 0b7c105a04ca ("usb: host: xhci: rename completion codes to match spec")
Signed-off-by: Mathias Nyman <mathias.nyman@linux.intel.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>

---
 drivers/usb/host/xhci-hub.c  |    2 +-
 drivers/usb/host/xhci-ring.c |    8 ++++----
 drivers/usb/host/xhci.c      |    8 ++++----
 3 files changed, 9 insertions(+), 9 deletions(-)

--- a/drivers/usb/host/xhci-hub.c
+++ b/drivers/usb/host/xhci-hub.c
@@ -421,7 +421,7 @@ static int xhci_stop_device(struct xhci_
 	wait_for_completion(cmd->completion);
 
 	if (cmd->status == COMP_COMMAND_ABORTED ||
-			cmd->status == COMP_STOPPED) {
+	    cmd->status == COMP_COMMAND_RING_STOPPED) {
 		xhci_warn(xhci, "Timeout while waiting for stop endpoint command\n");
 		ret = -ETIME;
 	}
--- a/drivers/usb/host/xhci-ring.c
+++ b/drivers/usb/host/xhci-ring.c
@@ -321,7 +321,7 @@ static void xhci_handle_stopped_cmd_ring
 		if (i_cmd->status != COMP_COMMAND_ABORTED)
 			continue;
 
-		i_cmd->status = COMP_STOPPED;
+		i_cmd->status = COMP_COMMAND_RING_STOPPED;
 
 		xhci_dbg(xhci, "Turn aborted command %p to no-op\n",
 			 i_cmd->command_trb);
@@ -1342,7 +1342,7 @@ static void handle_cmd_completion(struct
 	cmd_comp_code = GET_COMP_CODE(le32_to_cpu(event->status));
 
 	/* If CMD ring stopped we own the trbs between enqueue and dequeue */
-	if (cmd_comp_code == COMP_STOPPED) {
+	if (cmd_comp_code == COMP_COMMAND_RING_STOPPED) {
 		complete_all(&xhci->cmd_ring_stop_completion);
 		return;
 	}
@@ -1397,8 +1397,8 @@ static void handle_cmd_completion(struct
 		break;
 	case TRB_CMD_NOOP:
 		/* Is this an aborted command turned to NO-OP? */
-		if (cmd->status == COMP_STOPPED)
-			cmd_comp_code = COMP_STOPPED;
+		if (cmd->status == COMP_COMMAND_RING_STOPPED)
+			cmd_comp_code = COMP_COMMAND_RING_STOPPED;
 		break;
 	case TRB_RESET_EP:
 		WARN_ON(slot_id != TRB_TO_SLOT_ID(
--- a/drivers/usb/host/xhci.c
+++ b/drivers/usb/host/xhci.c
@@ -1805,7 +1805,7 @@ static int xhci_configure_endpoint_resul
 
 	switch (*cmd_status) {
 	case COMP_COMMAND_ABORTED:
-	case COMP_STOPPED:
+	case COMP_COMMAND_RING_STOPPED:
 		xhci_warn(xhci, "Timeout while waiting for configure endpoint command\n");
 		ret = -ETIME;
 		break;
@@ -1856,7 +1856,7 @@ static int xhci_evaluate_context_result(
 
 	switch (*cmd_status) {
 	case COMP_COMMAND_ABORTED:
-	case COMP_STOPPED:
+	case COMP_COMMAND_RING_STOPPED:
 		xhci_warn(xhci, "Timeout while waiting for evaluate context command\n");
 		ret = -ETIME;
 		break;
@@ -3478,7 +3478,7 @@ int xhci_discover_or_reset_device(struct
 	ret = reset_device_cmd->status;
 	switch (ret) {
 	case COMP_COMMAND_ABORTED:
-	case COMP_STOPPED:
+	case COMP_COMMAND_RING_STOPPED:
 		xhci_warn(xhci, "Timeout waiting for reset device command\n");
 		ret = -ETIME;
 		goto command_cleanup;
@@ -3845,7 +3845,7 @@ static int xhci_setup_device(struct usb_
 	 */
 	switch (command->status) {
 	case COMP_COMMAND_ABORTED:
-	case COMP_STOPPED:
+	case COMP_COMMAND_RING_STOPPED:
 		xhci_warn(xhci, "Timeout while waiting for setup device command\n");
 		ret = -ETIME;
 		break;

[toc] | [prev] | [next] | [standalone]


#1648925 — [PATCH 4.11 108/197] iio: proximity: as3935: fix as3935_write

FromGreg Kroah-Hartman <gregkh@linuxfoundation.org>
Date2017-05-24 00:20 +0200
Subject[PATCH 4.11 108/197] iio: proximity: as3935: fix as3935_write
Message-ID<tKqjM-1dD-31@gated-at.bofh.it>
In reply to#1648416
4.11-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Matt Ranostay <matt.ranostay@konsulko.com>

commit 84ca8e364acb26aba3292bc113ca8ed4335380fd upstream.

AS3935_WRITE_DATA macro bit is incorrect and the actual write
sequence is two leading zeros.

Cc: George McCollister <george.mccollister@gmail.com>
Signed-off-by: Matt Ranostay <matt.ranostay@konsulko.com>
Signed-off-by: Jonathan Cameron <jic23@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>

---
 drivers/iio/proximity/as3935.c |    3 +--
 1 file changed, 1 insertion(+), 2 deletions(-)

--- a/drivers/iio/proximity/as3935.c
+++ b/drivers/iio/proximity/as3935.c
@@ -50,7 +50,6 @@
 #define AS3935_TUNE_CAP		0x08
 #define AS3935_CALIBRATE	0x3D
 
-#define AS3935_WRITE_DATA	BIT(15)
 #define AS3935_READ_DATA	BIT(14)
 #define AS3935_ADDRESS(x)	((x) << 8)
 
@@ -105,7 +104,7 @@ static int as3935_write(struct as3935_st
 {
 	u8 *buf = st->buf;
 
-	buf[0] = (AS3935_WRITE_DATA | AS3935_ADDRESS(reg)) >> 8;
+	buf[0] = AS3935_ADDRESS(reg) >> 8;
 	buf[1] = val;
 
 	return spi_write(st->spi, buf, 2);

[toc] | [prev] | [next] | [standalone]


#1648926 — [PATCH 4.11 141/197] ARM: dts: at91: sama5d3_xplained: not all ADC channels are available

FromGreg Kroah-Hartman <gregkh@linuxfoundation.org>
Date2017-05-24 00:20 +0200
Subject[PATCH 4.11 141/197] ARM: dts: at91: sama5d3_xplained: not all ADC channels are available
Message-ID<tKqjM-1dD-33@gated-at.bofh.it>
In reply to#1648416
4.11-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Ludovic Desroches <ludovic.desroches@microchip.com>

commit d3df1ec06353e51fc44563d2e7e18d42811af290 upstream.

Remove ADC channels that are not available by default on the sama5d3_xplained
board (resistor not populated) in order to not create confusion.

Signed-off-by: Ludovic Desroches <ludovic.desroches@microchip.com>
Acked-by: Nicolas Ferre <nicolas.ferre@microchip.com>
Signed-off-by: Alexandre Belloni <alexandre.belloni@free-electrons.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>

---
 arch/arm/boot/dts/at91-sama5d3_xplained.dts |    4 +---
 1 file changed, 1 insertion(+), 3 deletions(-)

--- a/arch/arm/boot/dts/at91-sama5d3_xplained.dts
+++ b/arch/arm/boot/dts/at91-sama5d3_xplained.dts
@@ -163,9 +163,9 @@
 
 			adc0: adc@f8018000 {
 				atmel,adc-vref = <3300>;
+				atmel,adc-channels-used = <0xfe>;
 				pinctrl-0 = <
 					&pinctrl_adc0_adtrg
-					&pinctrl_adc0_ad0
 					&pinctrl_adc0_ad1
 					&pinctrl_adc0_ad2
 					&pinctrl_adc0_ad3
@@ -173,8 +173,6 @@
 					&pinctrl_adc0_ad5
 					&pinctrl_adc0_ad6
 					&pinctrl_adc0_ad7
-					&pinctrl_adc0_ad8
-					&pinctrl_adc0_ad9
 					>;
 				status = "okay";
 			};

[toc] | [prev] | [next] | [standalone]


#1648927 — [PATCH 4.11 135/197] KVM: arm/arm64: vgic-v3: Do not use Active+Pending state for a HW interrupt

FromGreg Kroah-Hartman <gregkh@linuxfoundation.org>
Date2017-05-24 00:20 +0200
Subject[PATCH 4.11 135/197] KVM: arm/arm64: vgic-v3: Do not use Active+Pending state for a HW interrupt
Message-ID<tKqjM-1dD-27@gated-at.bofh.it>
In reply to#1648416
4.11-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Marc Zyngier <marc.zyngier@arm.com>

commit 3d6e77ad1489650afa20da92bb589c8778baa8da upstream.

When an interrupt is injected with the HW bit set (indicating that
deactivation should be propagated to the physical distributor),
special care must be taken so that we never mark the corresponding
LR with the Active+Pending state (as the pending state is kept in
the physycal distributor).

Fixes: 59529f69f504 ("KVM: arm/arm64: vgic-new: Add GICv3 world switch backend")
Signed-off-by: Marc Zyngier <marc.zyngier@arm.com>
Reviewed-by: Christoffer Dall <cdall@linaro.org>
Signed-off-by: Christoffer Dall <cdall@linaro.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>

---
 virt/kvm/arm/vgic/vgic-v3.c |    7 +++++++
 1 file changed, 7 insertions(+)

--- a/virt/kvm/arm/vgic/vgic-v3.c
+++ b/virt/kvm/arm/vgic/vgic-v3.c
@@ -149,6 +149,13 @@ void vgic_v3_populate_lr(struct kvm_vcpu
 	if (irq->hw) {
 		val |= ICH_LR_HW;
 		val |= ((u64)irq->hwintid) << ICH_LR_PHYS_ID_SHIFT;
+		/*
+		 * Never set pending+active on a HW interrupt, as the
+		 * pending state is kept at the physical distributor
+		 * level.
+		 */
+		if (irq->active && irq_is_pending(irq))
+			val &= ~ICH_LR_PENDING_BIT;
 	} else {
 		if (irq->config == VGIC_CONFIG_LEVEL)
 			val |= ICH_LR_EOI;

[toc] | [prev] | [next] | [standalone]


#1648929 — [PATCH 4.11 143/197] arm64: dts: hi6220: Reset the mmc hosts

FromGreg Kroah-Hartman <gregkh@linuxfoundation.org>
Date2017-05-24 00:20 +0200
Subject[PATCH 4.11 143/197] arm64: dts: hi6220: Reset the mmc hosts
Message-ID<tKqjM-1dD-37@gated-at.bofh.it>
In reply to#1648416
4.11-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Daniel Lezcano <daniel.lezcano@linaro.org>

commit 0fbdf9953b41c28845fe8d05007ff09634ee3000 upstream.

The MMC hosts could be left in an unconsistent or uninitialized state from
the firmware. Instead of assuming, the firmware did the right things, let's
reset the host controllers.

This change fixes a bug when the mmc2/sdio is initialized leading to a hung
task:

[  242.704294] INFO: task kworker/7:1:675 blocked for more than 120 seconds.
[  242.711129]       Not tainted 4.9.0-rc8-00017-gcf0251f #3
[  242.716571] "echo 0 > /proc/sys/kernel/hung_task_timeout_secs" disables this message.
[  242.724435] kworker/7:1     D    0   675      2 0x00000000
[  242.729973] Workqueue: events_freezable mmc_rescan
[  242.734796] Call trace:
[  242.737269] [<ffff00000808611c>] __switch_to+0xa8/0xb4
[  242.742437] [<ffff000008d07c04>] __schedule+0x1c0/0x67c
[  242.747689] [<ffff000008d08254>] schedule+0x40/0xa0
[  242.752594] [<ffff000008d0b284>] schedule_timeout+0x1c4/0x35c
[  242.758366] [<ffff000008d08e38>] wait_for_common+0xd0/0x15c
[  242.763964] [<ffff000008d09008>] wait_for_completion+0x28/0x34
[  242.769825] [<ffff000008a1a9f4>] mmc_wait_for_req_done+0x40/0x124
[  242.775949] [<ffff000008a1ab98>] mmc_wait_for_req+0xc0/0xf8
[  242.781549] [<ffff000008a1ac3c>] mmc_wait_for_cmd+0x6c/0x84
[  242.787149] [<ffff000008a26610>] mmc_io_rw_direct_host+0x9c/0x114
[  242.793270] [<ffff000008a26aa0>] sdio_reset+0x34/0x7c
[  242.798347] [<ffff000008a1d46c>] mmc_rescan+0x2fc/0x360

[ ... ]

Signed-off-by: Daniel Lezcano <daniel.lezcano@linaro.org>
Signed-off-by: Wei Xu <xuwei5@hisilicon.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>

---
 arch/arm64/boot/dts/hisilicon/hi6220.dtsi |    3 +++
 1 file changed, 3 insertions(+)

--- a/arch/arm64/boot/dts/hisilicon/hi6220.dtsi
+++ b/arch/arm64/boot/dts/hisilicon/hi6220.dtsi
@@ -774,6 +774,7 @@
 			clocks = <&sys_ctrl 2>, <&sys_ctrl 1>;
 			clock-names = "ciu", "biu";
 			resets = <&sys_ctrl PERIPH_RSTDIS0_MMC0>;
+			reset-names = "reset";
 			bus-width = <0x8>;
 			vmmc-supply = <&ldo19>;
 			pinctrl-names = "default";
@@ -797,6 +798,7 @@
 			clocks = <&sys_ctrl 4>, <&sys_ctrl 3>;
 			clock-names = "ciu", "biu";
 			resets = <&sys_ctrl PERIPH_RSTDIS0_MMC1>;
+			reset-names = "reset";
 			vqmmc-supply = <&ldo7>;
 			vmmc-supply = <&ldo10>;
 			bus-width = <0x4>;
@@ -815,6 +817,7 @@
 			clocks = <&sys_ctrl HI6220_MMC2_CIUCLK>, <&sys_ctrl HI6220_MMC2_CLK>;
 			clock-names = "ciu", "biu";
 			resets = <&sys_ctrl PERIPH_RSTDIS0_MMC2>;
+			reset-names = "reset";
 			bus-width = <0x4>;
 			broken-cd;
 			pinctrl-names = "default", "idle";

[toc] | [prev] | [next] | [standalone]


#1648930 — [PATCH 4.11 122/197] powerpc/mm: Ensure IRQs are off in switch_mm()

FromGreg Kroah-Hartman <gregkh@linuxfoundation.org>
Date2017-05-24 00:20 +0200
Subject[PATCH 4.11 122/197] powerpc/mm: Ensure IRQs are off in switch_mm()
Message-ID<tKqjM-1dD-39@gated-at.bofh.it>
In reply to#1648416
4.11-stable review patch.  If anyone has any objections, please let me know.

------------------

From: David Gibson <david@gibson.dropbear.id.au>

commit 9765ad134a00a01cbcc69c78ff6defbfad209bc5 upstream.

powerpc expects IRQs to already be (soft) disabled when switch_mm() is
called, as made clear in the commit message of 9c1e105238c4 ("powerpc: Allow
perf_counters to access user memory at interrupt time").

Aside from any race conditions that might exist between switch_mm() and an IRQ,
there is also an unconditional hard_irq_disable() in switch_slb(). If that isn't
followed at some point by an IRQ enable then interrupts will remain disabled
until we return to userspace.

It is true that when switch_mm() is called from the scheduler IRQs are off, but
not when it's called by use_mm(). Looking closer we see that last year in commit
f98db6013c55 ("sched/core: Add switch_mm_irqs_off() and use it in the scheduler")
this was made more explicit by the addition of switch_mm_irqs_off() which is now
called by the scheduler, vs switch_mm() which is used by use_mm().

Arguably it is a bug in use_mm() to call switch_mm() in a different context than
it expects, but fixing that will take time.

This was discovered recently when vhost started throwing warnings such as:

  BUG: sleeping function called from invalid context at kernel/mutex.c:578
  in_atomic(): 0, irqs_disabled(): 1, pid: 10768, name: vhost-10760
  no locks held by vhost-10760/10768.
  irq event stamp: 10
  hardirqs last  enabled at (9):  _raw_spin_unlock_irq+0x40/0x80
  hardirqs last disabled at (10): switch_slb+0x2e4/0x490
  softirqs last  enabled at (0):  copy_process+0x5e8/0x1260
  softirqs last disabled at (0):  (null)
  Call Trace:
    show_stack+0x88/0x390 (unreliable)
    dump_stack+0x30/0x44
    __might_sleep+0x1c4/0x2d0
    mutex_lock_nested+0x74/0x5c0
    cgroup_attach_task_all+0x5c/0x180
    vhost_attach_cgroups_work+0x58/0x80 [vhost]
    vhost_worker+0x24c/0x3d0 [vhost]
    kthread+0xec/0x100
    ret_from_kernel_thread+0x5c/0xd4

Prior to commit 04b96e5528ca ("vhost: lockless enqueuing") (Aug 2016) the
vhost_worker() would do a spin_unlock_irq() not long after calling use_mm(),
which had the effect of reenabling IRQs. Since that commit removed the locking
in vhost_worker() the body of the vhost_worker() loop now runs with interrupts
off causing the warnings.

This patch addresses the problem by making the powerpc code mirror the x86 code,
ie. we disable interrupts in switch_mm(), and optimise the scheduler case by
defining switch_mm_irqs_off().

Signed-off-by: David Gibson <david@gibson.dropbear.id.au>
[mpe: Flesh out/rewrite change log, add stable]
Signed-off-by: Michael Ellerman <mpe@ellerman.id.au>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>

---
 arch/powerpc/include/asm/mmu_context.h |   17 +++++++++++++++--
 1 file changed, 15 insertions(+), 2 deletions(-)

--- a/arch/powerpc/include/asm/mmu_context.h
+++ b/arch/powerpc/include/asm/mmu_context.h
@@ -70,8 +70,9 @@ extern void drop_cop(unsigned long acop,
  * switch_mm is the entry point called from the architecture independent
  * code in kernel/sched/core.c
  */
-static inline void switch_mm(struct mm_struct *prev, struct mm_struct *next,
-			     struct task_struct *tsk)
+static inline void switch_mm_irqs_off(struct mm_struct *prev,
+				      struct mm_struct *next,
+				      struct task_struct *tsk)
 {
 	/* Mark this context has been used on the new CPU */
 	if (!cpumask_test_cpu(smp_processor_id(), mm_cpumask(next)))
@@ -110,6 +111,18 @@ static inline void switch_mm(struct mm_s
 	switch_mmu_context(prev, next, tsk);
 }
 
+static inline void switch_mm(struct mm_struct *prev, struct mm_struct *next,
+			     struct task_struct *tsk)
+{
+	unsigned long flags;
+
+	local_irq_save(flags);
+	switch_mm_irqs_off(prev, next, tsk);
+	local_irq_restore(flags);
+}
+#define switch_mm_irqs_off switch_mm_irqs_off
+
+
 #define deactivate_mm(tsk,mm)	do { } while (0)
 
 /*

[toc] | [prev] | [next] | [standalone]


#1648931 — [PATCH 4.11 116/197] [media] dvb-frontends/cxd2841er: define symbol_rate_min/max in T/C fe-ops

FromGreg Kroah-Hartman <gregkh@linuxfoundation.org>
Date2017-05-24 00:20 +0200
Subject[PATCH 4.11 116/197] [media] dvb-frontends/cxd2841er: define symbol_rate_min/max in T/C fe-ops
Message-ID<tKqjM-1dD-41@gated-at.bofh.it>
In reply to#1648416
4.11-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Daniel Scheller <d.scheller@gmx.net>

commit 158f0328af86a99d64073851967a02694bff987d upstream.

Fixes "w_scan -f c" complaining with

  This dvb driver is *buggy*: the symbol rate limits are undefined - please
  report to linuxtv.org)

Signed-off-by: Daniel Scheller <d.scheller@gmx.net>
Acked-by: Abylay Ospan <aospan@netup.ru>
Signed-off-by: Mauro Carvalho Chehab <mchehab@s-opensource.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>

---
 drivers/media/dvb-frontends/cxd2841er.c |    4 +++-
 1 file changed, 3 insertions(+), 1 deletion(-)

--- a/drivers/media/dvb-frontends/cxd2841er.c
+++ b/drivers/media/dvb-frontends/cxd2841er.c
@@ -3852,7 +3852,9 @@ static struct dvb_frontend_ops cxd2841er
 			FE_CAN_MUTE_TS |
 			FE_CAN_2G_MODULATION,
 		.frequency_min = 42000000,
-		.frequency_max = 1002000000
+		.frequency_max = 1002000000,
+		.symbol_rate_min = 870000,
+		.symbol_rate_max = 11700000
 	},
 	.init = cxd2841er_init_tc,
 	.sleep = cxd2841er_sleep_tc,

[toc] | [prev] | [next] | [standalone]


#1648932 — [PATCH 4.11 121/197] [media] cx231xx-cards: fix NULL-deref at probe

FromGreg Kroah-Hartman <gregkh@linuxfoundation.org>
Date2017-05-24 00:20 +0200
Subject[PATCH 4.11 121/197] [media] cx231xx-cards: fix NULL-deref at probe
Message-ID<tKqjN-1dD-43@gated-at.bofh.it>
In reply to#1648416
4.11-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Johan Hovold <johan@kernel.org>

commit 0cd273bb5e4d1828efaaa8dfd11b7928131ed149 upstream.

Make sure to check the number of endpoints to avoid dereferencing a
NULL-pointer or accessing memory beyond the endpoint array should a
malicious device lack the expected endpoints.

Fixes: e0d3bafd0258 ("V4L/DVB (10954): Add cx231xx USB driver")

Cc: Sri Deevi <Srinivasa.Deevi@conexant.com>
Signed-off-by: Johan Hovold <johan@kernel.org>
Signed-off-by: Hans Verkuil <hans.verkuil@cisco.com>
Signed-off-by: Mauro Carvalho Chehab <mchehab@s-opensource.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>

---
 drivers/media/usb/cx231xx/cx231xx-cards.c |   45 ++++++++++++++++++++++++++----
 1 file changed, 40 insertions(+), 5 deletions(-)

--- a/drivers/media/usb/cx231xx/cx231xx-cards.c
+++ b/drivers/media/usb/cx231xx/cx231xx-cards.c
@@ -1426,6 +1426,9 @@ static int cx231xx_init_v4l2(struct cx23
 
 	uif = udev->actconfig->interface[idx];
 
+	if (uif->altsetting[0].desc.bNumEndpoints < isoc_pipe + 1)
+		return -ENODEV;
+
 	dev->video_mode.end_point_addr = uif->altsetting[0].endpoint[isoc_pipe].desc.bEndpointAddress;
 	dev->video_mode.num_alt = uif->num_altsetting;
 
@@ -1439,7 +1442,12 @@ static int cx231xx_init_v4l2(struct cx23
 		return -ENOMEM;
 
 	for (i = 0; i < dev->video_mode.num_alt; i++) {
-		u16 tmp = le16_to_cpu(uif->altsetting[i].endpoint[isoc_pipe].desc.wMaxPacketSize);
+		u16 tmp;
+
+		if (uif->altsetting[i].desc.bNumEndpoints < isoc_pipe + 1)
+			return -ENODEV;
+
+		tmp = le16_to_cpu(uif->altsetting[i].endpoint[isoc_pipe].desc.wMaxPacketSize);
 		dev->video_mode.alt_max_pkt_size[i] = (tmp & 0x07ff) * (((tmp & 0x1800) >> 11) + 1);
 		dev_dbg(dev->dev,
 			"Alternate setting %i, max size= %i\n", i,
@@ -1456,6 +1464,9 @@ static int cx231xx_init_v4l2(struct cx23
 	}
 	uif = udev->actconfig->interface[idx];
 
+	if (uif->altsetting[0].desc.bNumEndpoints < isoc_pipe + 1)
+		return -ENODEV;
+
 	dev->vbi_mode.end_point_addr =
 	    uif->altsetting[0].endpoint[isoc_pipe].desc.
 			bEndpointAddress;
@@ -1472,8 +1483,12 @@ static int cx231xx_init_v4l2(struct cx23
 		return -ENOMEM;
 
 	for (i = 0; i < dev->vbi_mode.num_alt; i++) {
-		u16 tmp =
-		    le16_to_cpu(uif->altsetting[i].endpoint[isoc_pipe].
+		u16 tmp;
+
+		if (uif->altsetting[i].desc.bNumEndpoints < isoc_pipe + 1)
+			return -ENODEV;
+
+		tmp = le16_to_cpu(uif->altsetting[i].endpoint[isoc_pipe].
 				desc.wMaxPacketSize);
 		dev->vbi_mode.alt_max_pkt_size[i] =
 		    (tmp & 0x07ff) * (((tmp & 0x1800) >> 11) + 1);
@@ -1493,6 +1508,9 @@ static int cx231xx_init_v4l2(struct cx23
 	}
 	uif = udev->actconfig->interface[idx];
 
+	if (uif->altsetting[0].desc.bNumEndpoints < isoc_pipe + 1)
+		return -ENODEV;
+
 	dev->sliced_cc_mode.end_point_addr =
 	    uif->altsetting[0].endpoint[isoc_pipe].desc.
 			bEndpointAddress;
@@ -1507,7 +1525,12 @@ static int cx231xx_init_v4l2(struct cx23
 		return -ENOMEM;
 
 	for (i = 0; i < dev->sliced_cc_mode.num_alt; i++) {
-		u16 tmp = le16_to_cpu(uif->altsetting[i].endpoint[isoc_pipe].
+		u16 tmp;
+
+		if (uif->altsetting[i].desc.bNumEndpoints < isoc_pipe + 1)
+			return -ENODEV;
+
+		tmp = le16_to_cpu(uif->altsetting[i].endpoint[isoc_pipe].
 				desc.wMaxPacketSize);
 		dev->sliced_cc_mode.alt_max_pkt_size[i] =
 		    (tmp & 0x07ff) * (((tmp & 0x1800) >> 11) + 1);
@@ -1676,6 +1699,11 @@ static int cx231xx_usb_probe(struct usb_
 		}
 		uif = udev->actconfig->interface[idx];
 
+		if (uif->altsetting[0].desc.bNumEndpoints < isoc_pipe + 1) {
+			retval = -ENODEV;
+			goto err_video_alt;
+		}
+
 		dev->ts1_mode.end_point_addr =
 		    uif->altsetting[0].endpoint[isoc_pipe].
 				desc.bEndpointAddress;
@@ -1693,7 +1721,14 @@ static int cx231xx_usb_probe(struct usb_
 		}
 
 		for (i = 0; i < dev->ts1_mode.num_alt; i++) {
-			u16 tmp = le16_to_cpu(uif->altsetting[i].
+			u16 tmp;
+
+			if (uif->altsetting[i].desc.bNumEndpoints < isoc_pipe + 1) {
+				retval = -ENODEV;
+				goto err_video_alt;
+			}
+
+			tmp = le16_to_cpu(uif->altsetting[i].
 						endpoint[isoc_pipe].desc.
 						wMaxPacketSize);
 			dev->ts1_mode.alt_max_pkt_size[i] =

[toc] | [prev] | [next] | [standalone]


#1648933 — [PATCH 4.11 131/197] powerpc/tm: Fix FP and VMX register corruption

FromGreg Kroah-Hartman <gregkh@linuxfoundation.org>
Date2017-05-24 00:20 +0200
Subject[PATCH 4.11 131/197] powerpc/tm: Fix FP and VMX register corruption
Message-ID<tKqjN-1dD-45@gated-at.bofh.it>
In reply to#1648416
4.11-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Michael Neuling <mikey@neuling.org>

commit f48e91e87e67b56bef63393d1a02c6e22c1d7078 upstream.

In commit dc3106690b20 ("powerpc: tm: Always use fp_state and vr_state
to store live registers"), a section of code was removed that copied
the current state to checkpointed state. That code should not have been
removed.

When an FP (Floating Point) unavailable is taken inside a transaction,
we need to abort the transaction. This is because at the time of the
tbegin, the FP state is bogus so the state stored in the checkpointed
registers is incorrect. To fix this, we treclaim (to get the
checkpointed GPRs) and then copy the thread_struct FP live state into
the checkpointed state. We then trecheckpoint so that the FP state is
correctly restored into the CPU.

The copying of the FP registers from live to checkpointed is what was
missing.

This simplifies the logic slightly from the original patch.
tm_reclaim_thread() will now always write the checkpointed FP
state. Either the checkpointed FP state will be written as part of
the actual treclaim (in tm.S), or it'll be a copy of the live
state. Which one we use is based on MSR[FP] from userspace.

Similarly for VMX.

Fixes: dc3106690b20 ("powerpc: tm: Always use fp_state and vr_state to store live registers")
Signed-off-by: Michael Neuling <mikey@neuling.org>
Reviewed-by: cyrilbur@gmail.com
Signed-off-by: Michael Ellerman <mpe@ellerman.id.au>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>

---
 arch/powerpc/kernel/process.c |   19 +++++++++++++++++++
 1 file changed, 19 insertions(+)

--- a/arch/powerpc/kernel/process.c
+++ b/arch/powerpc/kernel/process.c
@@ -864,6 +864,25 @@ static void tm_reclaim_thread(struct thr
 	if (!MSR_TM_SUSPENDED(mfmsr()))
 		return;
 
+	/*
+	 * If we are in a transaction and FP is off then we can't have
+	 * used FP inside that transaction. Hence the checkpointed
+	 * state is the same as the live state. We need to copy the
+	 * live state to the checkpointed state so that when the
+	 * transaction is restored, the checkpointed state is correct
+	 * and the aborted transaction sees the correct state. We use
+	 * ckpt_regs.msr here as that's what tm_reclaim will use to
+	 * determine if it's going to write the checkpointed state or
+	 * not. So either this will write the checkpointed registers,
+	 * or reclaim will. Similarly for VMX.
+	 */
+	if ((thr->ckpt_regs.msr & MSR_FP) == 0)
+		memcpy(&thr->ckfp_state, &thr->fp_state,
+		       sizeof(struct thread_fp_state));
+	if ((thr->ckpt_regs.msr & MSR_VEC) == 0)
+		memcpy(&thr->ckvr_state, &thr->vr_state,
+		       sizeof(struct thread_vr_state));
+
 	giveup_all(container_of(thr, struct task_struct, thread));
 
 	tm_reclaim(thr, thr->ckpt_regs.msr, cause);

[toc] | [prev] | [next] | [standalone]


#1648934 — [PATCH 4.11 123/197] powerpc/eeh: Avoid use after free in eeh_handle_special_event()

FromGreg Kroah-Hartman <gregkh@linuxfoundation.org>
Date2017-05-24 00:20 +0200
Subject[PATCH 4.11 123/197] powerpc/eeh: Avoid use after free in eeh_handle_special_event()
Message-ID<tKqjN-1dD-49@gated-at.bofh.it>
In reply to#1648416
4.11-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Russell Currey <ruscur@russell.cc>

commit daeba2956f32f91f3493788ff6ee02fb1b2f02fa upstream.

eeh_handle_special_event() is called when an EEH event is detected but
can't be narrowed down to a specific PE.  This function looks through
every PE to find one in an erroneous state, then calls the regular event
handler eeh_handle_normal_event() once it knows which PE has an error.

However, if eeh_handle_normal_event() found that the PE cannot possibly
be recovered, it will free it, rendering the passed PE stale.
This leads to a use after free in eeh_handle_special_event() as it attempts to
clear the "recovering" state on the PE after eeh_handle_normal_event() returns.

Thus, make sure the PE is valid when attempting to clear state in
eeh_handle_special_event().

Fixes: 8a6b1bc70dbb ("powerpc/eeh: EEH core to handle special event")
Reported-by: Alexey Kardashevskiy <aik@ozlabs.ru>
Signed-off-by: Russell Currey <ruscur@russell.cc>
Reviewed-by: Gavin Shan <gwshan@linux.vnet.ibm.com>
Signed-off-by: Michael Ellerman <mpe@ellerman.id.au>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>

---
 arch/powerpc/kernel/eeh_driver.c |   19 +++++++++++++++----
 1 file changed, 15 insertions(+), 4 deletions(-)

--- a/arch/powerpc/kernel/eeh_driver.c
+++ b/arch/powerpc/kernel/eeh_driver.c
@@ -724,7 +724,7 @@ static int eeh_reset_device(struct eeh_p
  */
 #define MAX_WAIT_FOR_RECOVERY 300
 
-static void eeh_handle_normal_event(struct eeh_pe *pe)
+static bool eeh_handle_normal_event(struct eeh_pe *pe)
 {
 	struct pci_bus *frozen_bus;
 	struct eeh_dev *edev, *tmp;
@@ -736,7 +736,7 @@ static void eeh_handle_normal_event(stru
 	if (!frozen_bus) {
 		pr_err("%s: Cannot find PCI bus for PHB#%x-PE#%x\n",
 			__func__, pe->phb->global_number, pe->addr);
-		return;
+		return false;
 	}
 
 	eeh_pe_update_time_stamp(pe);
@@ -870,7 +870,7 @@ static void eeh_handle_normal_event(stru
 	pr_info("EEH: Notify device driver to resume\n");
 	eeh_pe_dev_traverse(pe, eeh_report_resume, NULL);
 
-	return;
+	return false;
 
 excess_failures:
 	/*
@@ -915,8 +915,12 @@ perm_error:
 			pci_lock_rescan_remove();
 			pci_hp_remove_devices(frozen_bus);
 			pci_unlock_rescan_remove();
+
+			/* The passed PE should no longer be used */
+			return true;
 		}
 	}
+	return false;
 }
 
 static void eeh_handle_special_event(void)
@@ -982,7 +986,14 @@ static void eeh_handle_special_event(voi
 		 */
 		if (rc == EEH_NEXT_ERR_FROZEN_PE ||
 		    rc == EEH_NEXT_ERR_FENCED_PHB) {
-			eeh_handle_normal_event(pe);
+			/*
+			 * eeh_handle_normal_event() can make the PE stale if it
+			 * determines that the PE cannot possibly be recovered.
+			 * Don't modify the PE state if that's the case.
+			 */
+			if (eeh_handle_normal_event(pe))
+				continue;
+
 			eeh_pe_state_clear(pe, EEH_PE_RECOVERING);
 		} else {
 			pci_lock_rescan_remove();

[toc] | [prev] | [next] | [standalone]


#1648935 — [PATCH 4.11 104/197] USB: serial: io_ti: fix div-by-zero in set_termios

FromGreg Kroah-Hartman <gregkh@linuxfoundation.org>
Date2017-05-24 00:20 +0200
Subject[PATCH 4.11 104/197] USB: serial: io_ti: fix div-by-zero in set_termios
Message-ID<tKqjN-1dD-47@gated-at.bofh.it>
In reply to#1648416
4.11-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Johan Hovold <johan@kernel.org>

commit 6aeb75e6adfaed16e58780309613a578fe1ee90b upstream.

Fix a division-by-zero in set_termios when debugging is enabled and a
high-enough speed has been requested so that the divisor value becomes
zero.

Instead of just fixing the offending debug statement, cap the baud rate
at the base as a zero divisor value also appears to crash the firmware.

Fixes: 1da177e4c3f4 ("Linux-2.6.12-rc2")
Reviewed-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
Signed-off-by: Johan Hovold <johan@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>

---
 drivers/usb/serial/io_ti.c |    5 ++++-
 1 file changed, 4 insertions(+), 1 deletion(-)

--- a/drivers/usb/serial/io_ti.c
+++ b/drivers/usb/serial/io_ti.c
@@ -2349,8 +2349,11 @@ static void change_port_settings(struct
 	if (!baud) {
 		/* pick a default, any default... */
 		baud = 9600;
-	} else
+	} else {
+		/* Avoid a zero divisor. */
+		baud = min(baud, 461550);
 		tty_encode_baud_rate(tty, baud, baud);
+	}
 
 	edge_port->baud_rate = baud;
 	config->wBaudRate = (__u16)((461550L + baud/2) / baud);

[toc] | [prev] | [next] | [standalone]


#1648936 — [PATCH 4.11 119/197] [media] cx231xx-audio: fix init error path

FromGreg Kroah-Hartman <gregkh@linuxfoundation.org>
Date2017-05-24 00:20 +0200
Subject[PATCH 4.11 119/197] [media] cx231xx-audio: fix init error path
Message-ID<tKqjN-1dD-51@gated-at.bofh.it>
In reply to#1648416
4.11-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Johan Hovold <johan@kernel.org>

commit fff1abc4d54e469140a699612b4db8d6397bfcba upstream.

Make sure to release the snd_card also on a late allocation error.

Fixes: e0d3bafd0258 ("V4L/DVB (10954): Add cx231xx USB driver")

Cc: Sri Deevi <Srinivasa.Deevi@conexant.com>
Signed-off-by: Johan Hovold <johan@kernel.org>
Signed-off-by: Hans Verkuil <hans.verkuil@cisco.com>
Signed-off-by: Mauro Carvalho Chehab <mchehab@s-opensource.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>

---
 drivers/media/usb/cx231xx/cx231xx-audio.c |   25 ++++++++++++++-----------
 1 file changed, 14 insertions(+), 11 deletions(-)

--- a/drivers/media/usb/cx231xx/cx231xx-audio.c
+++ b/drivers/media/usb/cx231xx/cx231xx-audio.c
@@ -670,10 +670,8 @@ static int cx231xx_audio_init(struct cx2
 
 	spin_lock_init(&adev->slock);
 	err = snd_pcm_new(card, "Cx231xx Audio", 0, 0, 1, &pcm);
-	if (err < 0) {
-		snd_card_free(card);
-		return err;
-	}
+	if (err < 0)
+		goto err_free_card;
 
 	snd_pcm_set_ops(pcm, SNDRV_PCM_STREAM_CAPTURE,
 			&snd_cx231xx_pcm_capture);
@@ -687,10 +685,9 @@ static int cx231xx_audio_init(struct cx2
 	INIT_WORK(&dev->wq_trigger, audio_trigger);
 
 	err = snd_card_register(card);
-	if (err < 0) {
-		snd_card_free(card);
-		return err;
-	}
+	if (err < 0)
+		goto err_free_card;
+
 	adev->sndcard = card;
 	adev->udev = dev->udev;
 
@@ -709,9 +706,10 @@ static int cx231xx_audio_init(struct cx2
 		"audio EndPoint Addr 0x%x, Alternate settings: %i\n",
 		adev->end_point_addr, adev->num_alt);
 	adev->alt_max_pkt_size = kmalloc(32 * adev->num_alt, GFP_KERNEL);
-
-	if (adev->alt_max_pkt_size == NULL)
-		return -ENOMEM;
+	if (!adev->alt_max_pkt_size) {
+		err = -ENOMEM;
+		goto err_free_card;
+	}
 
 	for (i = 0; i < adev->num_alt; i++) {
 		u16 tmp =
@@ -725,6 +723,11 @@ static int cx231xx_audio_init(struct cx2
 	}
 
 	return 0;
+
+err_free_card:
+	snd_card_free(card);
+
+	return err;
 }
 
 static int cx231xx_audio_fini(struct cx231xx *dev)

[toc] | [prev] | [next] | [standalone]


#1648937 — [PATCH 4.11 113/197] [media] s5p-mfc: Fix unbalanced call to clock management

FromGreg Kroah-Hartman <gregkh@linuxfoundation.org>
Date2017-05-24 00:20 +0200
Subject[PATCH 4.11 113/197] [media] s5p-mfc: Fix unbalanced call to clock management
Message-ID<tKqjN-1dD-53@gated-at.bofh.it>
In reply to#1648416
4.11-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Marek Szyprowski <m.szyprowski@samsung.com>

commit a5cb00eb4223458250b55daf03ac7ea5f424d601 upstream.

Clock should be turned off after calling s5p_mfc_init_hw() from the
watchdog worker, like it is already done in the s5p_mfc_open() which also
calls this function.

Fixes: af93574678108 ("[media] MFC: Add MFC 5.1 V4L2 driver")

Signed-off-by: Marek Szyprowski <m.szyprowski@samsung.com>
Signed-off-by: Sylwester Nawrocki <s.nawrocki@samsung.com>
Signed-off-by: Mauro Carvalho Chehab <mchehab@s-opensource.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>

---
 drivers/media/platform/s5p-mfc/s5p_mfc.c |    1 +
 1 file changed, 1 insertion(+)

--- a/drivers/media/platform/s5p-mfc/s5p_mfc.c
+++ b/drivers/media/platform/s5p-mfc/s5p_mfc.c
@@ -206,6 +206,7 @@ static void s5p_mfc_watchdog_worker(stru
 		}
 		s5p_mfc_clock_on();
 		ret = s5p_mfc_init_hw(dev);
+		s5p_mfc_clock_off();
 		if (ret)
 			mfc_err("Failed to reinit FW\n");
 	}

[toc] | [prev] | [next] | [standalone]


Page 6 of 9 — ← Prev page 1 2 3 4 5 [6] 7 8 9  Next page →

Back to top | Article view | linux.kernel


csiph-web